craftcms/cms is vulnerable to Missing Authorization
35
Low Risk
The reorder-sets action in Craft CMS's globals controller lacks the admin authorization check that the adjacent save and delete actions enforce. Any authenticated control-panel user can reorder all global sets, and the new order is written through to the versioned project config and persists across requests. This lets a low-privilege user create project-config churn, trigger config-sync conflicts, and change the ordering shown to all editors. The fix adds the missing admin requirement to the action.
You are affected if you are using a version that falls within the vulnerable range and authenticated control-panel users can call the globals reorder-sets action.
craftcms/cms is vulnerable to Missing Authorization in versions 4.0.0 - 4.18.0.1 and 5.0.0 - 5.10.2.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant